Re: A more fundamental issue..

Marius Huse Jacobsen <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
Hello Jeroen,

Wednesday, November 5, 2003, 3:20:33 PM, you wrote:

JvD> As computing become ever more powerful and oop scripting languages ever more
JvD> prevalent and simple, more and more programmers will know less about OS & 
JvD> library component  fundamentals. As computing becomes ever more pervasive, 
JvD> the security of code in the OS & library components will over the years only 
JvD> become more important while becoming the domain of an ever more exclusive 
JvD> club (because their members are mainly highly experienced C/C++ programmers).

So, if things don't change direction, you fear that the entire
industry (or would you say the entire world?) will depend on a few
'gurus' to maintain the link between the low-level and the high-level
in a secure fashion?

<snip>

JvD> This century will most likely see advanced,
JvD> intimate human interface technologies introduced, and once they are available 
JvD> their benefits will most likely mandate their use.

Let me add one line to this:

For those that can afford it.

JvD> And so we program in ever higher scripting abstractions, we interface ever
JvD> closer to and into our skins and minds, we integrate systems ever closer to 
JvD> rely on and reuse of each other. All this is built on increasingly complex 
JvD> layers in the OS and in library toolkits. 

And the fewer that understands the 'connectors' between high-level and
low-level parts of the system, the bigger the potential problems, is
that what you're saying?

Reuse will also reuse the bugs?

A system that depends on a faulty system is a system that could fail
any moment?

<moved>
JvD> These technologies will
JvD> most likely aim to wire us directly into the computer.

JvD> As computing becomes ever more pervasive, even intimate, exploits can lead to 
JvD> increasing disaster.

Have you seen the anime "Ghost in the shell" ?

For those who haven't, I'll summarize the relevant parts. For most of
it, at least the beginning, there is a hunt for a "ghost hacker", one
who hacks ghosts. Ghosts being the digitized minds of people, that can
be downloaded into a host - just think of it as a human-looking robot.
In that way, you could travel around the world in the time it took to
transfer your brain data to the new 'host'.

In that anime, that ghost hacker replaced memories, among other things
- not something that I'd expect we'll see until we have a full
conversion wetware->software happening. In the setting, this had
already happened.

I'm not going to say much more, as that could spoil the fun for those
who have yet to see it.


The problem is, under the conditions in the setting of the anime, it
is a realistic scenario. Until the wetware to software conversion
happens though, I can think of a few ventures...

First of all, a specific part of the entertainment industry would love
the ability to introduce specific arbitrary feelings to your nerves.
Secondly, there's the opposite. For interrogation or any other
purpose, it would be a good tool for torture. Feeling safe already?

For that sort of reason, you'd have to make sure security really kept
up, and with todays standard for computer security... it's perhaps
better left unsaid.

JvD> Our mode of thinking about security may have kept up to date with the
JvD> requirements but isn't yet really taking the foreseeable evolution and 
JvD> convergence of computing and other sciences into account. Computing security 
JvD> is becoming a political concern but that concern is still too shallow and 
JvD> mainly has to do with issues such as 'bundling', 'sharing' and 'digital 
JvD> rights'.

Instead of? Accountability?

JvD> The OS and library components are becoming open, public 
JvD> infrastructure but the trend is at risk from the current political focus on 
JvD> private instead of public ownership protection. 

JvD> Security socially is about accountability and transparency. Programmers and 
JvD> the politicians now are setting the mold for other sciences to follow. 
JvD> Especially the science of genetic and bioengineering requires a much more 
JvD> accountable mold before its products can become as ubiquitous as our 
JvD> handywork.

I'm shuddering at the thought of those sciences having the same
standard of security as computer software. ("as is")

I think microsoft would be in big trouble if they could be held
accountable for the security problems in their software.

JvD> If we are to see the same lack of security professionalism and a 
JvD> similar level of expediency in bioindustries as we see in the software 
JvD> industry we have a lot more to fear from vulnerabilities and exploits and 
JvD> lack of patches there. Hopefully in the nearby future we have enough OS & 
JvD> library knowhow of our own internals so that we can patch something like Sars 
JvD> quickly. The need for that knowhow to be "open source" is evident otherwise 
JvD> we as a species could be ransom to profiteering.

Because only those who could pay the most would get cures.

I think that part lost much of its link to computer security,

JvD> ps: I've gone through a couple of drafts, don't mean to cry wolf, but we are 
JvD> on the eve of our development model spilling over into other sciences that 
JvD> increasingly use computing in development and manufacturing.

Seems to me that most use computers as tools, and are luckily not
copying our software making processes. Therefore, it seems to me like
a cry of wolf. I could be wrong in my perceptions, though.

One thing about the comparison to the biotech and GenEng branches, is
that one can avoid computer software vulnerabilities completely - by
ditching computers totally. You can hardly avoid biotech when their
wee ones come to get you!

JvD> It's a fairly 
JvD> alarming trend considering that we as a society seem to spend more media time 
JvD> on security issues within our computers than in our biosphere.

Is that so? Well, seems to me that there is more knowledge around
about it too - both what we know the most about, and what 'people in
general' knows. It's a lot more 'absolute' when applying the word to
the knowledge (as opposed to the effects). Therefore, it's less
obscure, and so it is more interesting.

Mass media spends time on what's interesting, not what's important.
Successful media either targets a specific (small) selection of
people, or covers things that are interesting instead of obscure.

JvD> It's also
JvD> alarming that after so much public scrutiny and debate we are still on the 
JvD> religious discourse of good and evil.

So that discussion is alive and kicking still?
I thought they had finally come to the conclusion that good and evil
could not be defined long ago.

-- 
Best regards,
 Marius                            mailto:[email protected]
--
They hunt the 'malicious' hackers,
leaving those who greedily earn lots 
of money on faulty products alone.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.